Socket.IO Vulnerability in Open WebUI Affects Permission Checks
CVE-2026-44564

5.4MEDIUM

Key Information:

Vendor

Open-webui

Vendor
CVE Published:
15 May 2026

What is CVE-2026-44564?

Open WebUI, a self-hosted AI platform, has a flaw in its Socket.IO event handling. Prior to version 0.9.0, the system fails to properly verify write permissions when users with read-only access join document rooms. This oversight allows such users to emit update events that can alter the document's state, affecting all connected collaborators in real time. The issue is resolved in version 0.9.0.

Affected Version(s)

open-webui < 0.9.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.